← University
Operational Risk Reporting for Boards and Executives
0 of 4

A mid-sized credit union headquartered in Red Deer, with 37 branches spread across central and northern Alberta, experienced a catastrophic technology failure on March 15, 2024. The incident began shortly after 9:00 AM when branch managers started reporting erratic behaviour in the core banking system, with some transactions processing normally while others were inexplicably rejected. Within 90 minutes, a routine backup procedure triggered an unexpected cascade failure that brought the entire digital infrastructure to a standstill. Members attempting to access accounts through online banking received error messages, debit card transactions at point-of-sale terminals throughout the province declined randomly, and tellers at physical branches found themselves unable to process even the simplest deposits or withdrawals.

The credit union's chief executive officer spent the morning fielding calls from branch managers while the information technology team worked to identify the source of the failure. By early afternoon, the organization had activated its business continuity protocols, but the damage to member confidence and operational capacity was already substantial. The board of directors received its first notification of the incident several hours after the initial reports from branch managers, and the information that reached them was fragmentary and inconsistent with what frontline staff were experiencing.

In the weeks following the incident, the board undertook a review of the circumstances that had led to the failure and the organizational response. That review revealed that warning signs had existed in the weeks and months prior to March 15. System performance metrics had shown gradual degradation, vendor support tickets had accumulated, and information technology staff had expressed concerns about infrastructure capacity in internal communications. None of this information had reached the board in a form that would have enabled meaningful oversight or intervention. The operational risk reports that the board had been receiving focused on a different set of concerns entirely and did not include the indicators that might have signalled the impending failure.

The credit union now faces a series of questions about how operational risk information flows through the organization. The board requires a reporting framework that provides visibility into the threats most likely to disrupt organizational objectives, without overwhelming directors with operational detail that obscures rather than illuminates. Management must determine which metrics and indicators capture meaningful risk exposure and how to present that information in formats that support governance rather than compliance theatre. Most critically, the organization must establish clear thresholds for escalation — criteria that determine which risks warrant board attention and which can be managed at lower levels of the organization without creating liability gaps or governance failures.

Escalation and Materiality: Deciding What Rises to Board Level

Every organization, regardless of size or sector, generates a continuous stream of information about operational risks. Some of these risks are routine matters handled effectively by frontline staff or middle management. Others carry implications so significant that they demand the attention of the board of directors or the most senior executives. The challenge that confronts risk managers, executive directors, and board chairs alike is determining which risks belong in each category. This determination process, known as escalation, depends fundamentally on understanding materiality—the threshold at which a risk becomes significant enough to warrant attention at the highest levels of organizational governance. Getting this distinction right protects the organization from both governance failures and operational paralysis. Getting it wrong exposes the board to liability for matters it should have known about, or alternatively, buries directors in operational minutiae that prevents them from fulfilling their strategic oversight responsibilities.

The concept of materiality originated in financial reporting contexts, where it describes information that would reasonably influence the decisions of users of financial statements. However, operational risk materiality extends well beyond financial considerations. A risk may be material because of its potential impact on organizational reputation, its implications for regulatory compliance, its effect on stakeholder relationships, or its connection to strategic objectives. The Canada Not-for-profit Corporations Act and the Canada Business Corporations Act, as of the date of authorship, both establish duties of care and diligence that require directors to be reasonably informed about material matters affecting the corporation. Provincial corporate statutes across British Columbia, Alberta, Saskatchewan, Ontario, and other common law provinces contain analogous provisions. Quebec's Civil Code establishes similar obligations for directors within its civil law framework, requiring administrators to act with prudence, diligence, honesty, and loyalty. These statutory duties create a legal foundation for materiality determinations, because directors who remain uninformed about material risks may be found to have breached their duty of care.

That’s the free preview

You’ve reached the end of what’s open to read. The rest of this lesson is part of a $79 course — purchasing unlocks it, or sign in if you already have access.